Our August 2023 newsletter goes over two very important topics including Neurodiversity in cyber security and the benefits, then how to best use your defences. Read below for more insightful content this month!
Neurodiversity in Cyber Security
With the concerns of cyber security skills shortages and the workforce gap, now is the time to see the potential benefits of recruiting those with neurodevelopmental disorders like ADHD, autism, dyspraxia and other conditions. It is estimated that around 15% of the UK’s population is neurodiverse, but it is difficult to know for certain how many are undiagnosed.
While these disorders present challenges in various areas of life, including academic and work, the advantages of several common characteristics of neurodivergent people such as pattern-spotting, visual-spatial thinking and creative insights are now being realised. For the purposes of this article, we will be focusing on ADHD and Autism Spectrum Disorder:
ADHD
A neurodevelopmental disorder which potentially causes a deficiency in dopamine production.
- Hyperfocus: A complete absorption in concentration, with an intense focus on a specific task or problem to a level where they appear to completely ignore everything else.
- Multitasking: While individuals may struggle with prolonged attention on a single task, they could excel at handling multiple tasks simultaneously without being overwhelmed.
- Creativity: Neurodiverse people often have unconventional and creative thinking styles. This could be useful for coming up with innovative solutions, or predicting various attack vectors or defenses against cyber-attacks.
- Rapid problem-solving: ADHD people are often quick thinkers, and can have a talent for quickly identifying & addressing issues. Being able to think on their feet can help them hastily respond to security incidents.
- High energy levels: They may have higher energy levels compared to others and often cope and remain composed in high-pressure situations.
- Adaptability: Individuals with ADHD have to adapt to the challenges of their condition daily. This can translate well into the constantly changing landscape of cyber security.
Asperger’s and Autism
Both of these conditions are encompassed under the broader term of Autism Spectrum Disorder (ASD).
- Attention to detail: Often possessing a keen eye for detail and excel at pattern recognition. This can be crucial for identifying suspicious activities, anomalies, or potential security breaches.
- Specialised interests: ASD individuals often develop a deep and intense interest in specific subjects. This passion can lead to strong expertise and knowledge in their chosen field.
- Logical and analytical thinking: It’s often found that ASD exhibit strong logical and analytical thinking skills. These are highly valuable for incident analysis or vulnerability assessment tasks.
- Persistence and focus: They commonly demonstrate persistence and determination when tackling complex problems.
- Adherence to rules & protocols: Many ASD individuals prefer clear rules and structured environments. In a career based around protocol and compliance, this can contribute to a secure and well-regulated environment.
- Low sensitivity to social engineering: Some with ASD may have difficulty recognising social cues and could translate into being less susceptible to social engineering tactics.
- Ethical mindset: ASD individuals often possess a strong moral sense of right and wrong. They are more likely to adhere to ethical practices and respect confidentiality and privacy in the cyber security field.
While these characteristics are common, it is essential to approach this topic with sensitivity and avoid generalisations or assumptions about anyone based on their neurodiversity.
Any and all conditions are highly individual and not everyone will experience the same advantages or disadvantages in any given context. While some may find ways to excel in specific aspects of their career out of necessity, it is crucial to support them in their strengths and provide necessary support to get the best out of anyone.
Best use of your defences
I love cricket, and I also love using anecdotes to help highlight how best to protect your company from cyber-attacks. I realised I have never mixed the two. So…
In cricket the fielding side is trying to prevent things from happening, where as the batting side are trying to ‘steal’ runs. So, you have two ‘hackers’ trying to beat the defences of the fielders to gain runs. My point being that while the defending side have more people on the field, no one is sure where the hackers are going to put the ball. So, they have to try and predict where the ball is going to be hit, but the area they cover is larger than the number of people available.
Familiarities in business
So, does any of this sound familiar? Your systems are protected by a limited number of services, whether the limitation is caused by lack of budget or lack of skills. Knowing where to place those resources to give you the best coverage is often impossible without some level of knowledge into the type of threats your organisation is facing.
In modern international cricket, the teams have statisticians to highlight the strengths and weaknesses of their opponents, so that the defending (fielding) team can focus on placing the limited resources in the best place to prevent the leaking of runs, and potentially try and force the hacker (batter) to make a mistake or put in place a plan to remove them before they cause too much damage (runs).
Risk Assessment and Threat Intelligence
In cyber security terms, this is risk assessment and threat intelligence. The importance of threat intelligence has been highlighted recently by it becoming an additional control that was included with the update to ISO27001 standard in 2023. While risk management helps identify your weaknesses, threat intelligence is identifying the hackers’ strengths.
While most organisations carry out a range of risk assessments to ensure the company can reduce those risks, threat intelligence is not part of most companies’ information security planning. There are free resources worth monitoring, such as NCSC’s Threat Reports, which explain things in a clear concise manor. One of the key things is to know the difference between risk and threat. Threat intelligence deals with understanding the methodology a cyber criminal is using, rather than risk which is about identifying the weaknesses in your protection.
Reducing Attacks
This combination of information helps you place your limited defensive resources in their most effective position, reducing your potential attack surface. Thereby reducing the possibility that your security will be hit for six and increasing the chances you will get the hacker out of your system, without losing any data (out for a duck.)
